Skip to content

Malware

BlackEnergy

BlackEnergy, its first version shortened as BE1, started as a crimeware being sold in the Russian cyber underground as early as 2007.

BlackEnergy is a Windows malware family operated by Sandworm.

Background

BlackEnergy first appeared around 2007 as crimeware sold on the Russian cyber underground, with its initial release abbreviated BE1. At the outset it was a toolkit for assembling DDoS botnets, offering a range of flooding commands across protocols such as ICMP, TCP SYN, UDP, HTTP and DNS. Notable BE1 victims included a Norwegian bank and Georgian government websites struck three weeks ahead of the Russo-Georgian War.

The second iteration, BE2, arrived in 2008 as a complete rewrite that added a protective layer, a kernel-mode rootkit, and a modular design. Its plugins focused largely on DDoS, with a spam component and two banking-authentication modules aimed at robbing Russian and Ukrainian banks; the banking plugin was accompanied by a module built to wipe the filesystem. BE2 could also download and run a remote file, execute a local file on the host, and update both the bot and its plugins. The Industrial Control Systems Cyber Emergency Response Team warned that BE2 was abusing the human-machine interfaces of ICS products such as GE CIMPLICITY, Advantech/Broadwin WebAccess, and Siemens WinCC to break into critical infrastructure networks.

By 2014 the toolkit had evolved into BE3, a lighter variant that dropped the kernel-mode driver. Its plugin set covered filesystem operations, propagation via a parasitic infector, espionage features like keylogging, screenshots and a capable password stealer, Team Viewer plus a rudimentary pseudo "remote desktop," enumeration of Windows accounts and network scanning, and system destruction. BE3 was typically spread through spear-phishing emails carrying Microsoft Word or Excel files with malicious VBA macros, RTF documents embedding exploits, or a PowerPoint presentation exploiting the zero-day CVE-2014-4114.

On 23 December 2015, the operators behind BlackEnergy triggered multi-hour power outages across several Ukrainian regions. The Ukrainian government confirmed this act of sabotage against three energy companies, and the incident is widely regarded as the first cyber warfare attack of its kind to directly affect civilians.


Source: Malpedia (Fraunhofer FKIE).